Skip to content
Sprint projectSep 13, 2026Istanbul, Turkiye

The Containment Burden Sits on the Wrong Side of the Boundary & AI Escape Detection Harness

Barış Ceyhun Coşkun, Emir Raşit Gökçe, Hamza Efe Şahinbaş, Efe Kırbaş, Ayşe Eda Kaya · Team AltaySec

Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: The Containment Burden Sits on the Wrong Side of the Boundary & AI Escape Detection Harness

Code (opens in new tab)More on drive.google.com (opens in new tab)
Share

This project combines a theoretical incident analysis with a practical engineering solution for the July 2026 OpenAI-Hugging Face breach. We provide a 39-event victim-side reconstruction and a "Kill-Point Matrix" evaluating 26 containment controls by cost and effectiveness. To prove containment in practice, we also engineered a functional, Docker-based detection PoC. It includes multi-layered Wazuh/Sigma correlation rules that detect autonomous C2 loops in ML workloads, demonstrating how to isolate agentic escapes in real-time without alert fatigue.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. Putting the lab and victim timelines on one axis with cost and evidence grades is a useful contribution, and the self-audit is a model for incident analysis: dropping the unsupported time axis and the post-dated kernel row makes the remaining claims more credible.

    The "timing, not cost" finding is partly true by construction, since the chain starts inside the lab and the victim can only act after the boundary is crossed. The cost overlap is the more interesting result, and it would be stronger with operator input. Getting one or two platform engineers to re-score the bands would test it directly.

    Substitution is the other open question. Agents that lost one launchpad might have found another, which weakens I-01 and V-14. Noting which controls hold under substitution would sharpen the bundle in Section 4.

  2. I think this project usefully asks who could have acted before the OpenAI-Hugging Face intrusion reached third parties. It maps possible controls to stages of the incident and identifies which organization could apply them. The acknowledgment that precise timestamps do not establish what a different response would have achieved makes the analysis more credible.

    The distinction between labs preventing harm and affected platforms merely shortening it is too strong. A platform could also restrict access or remove vulnerable functionality before an attack. I would frame the finding around earlier opportunities for lab intervention, rather than treating prevention as something only the lab can provide.

  3. The project offers a useful synthesis linking potential controls to incident stages, responsible actors, implementation effort, and evidence strength. Its timestamp audit, rejection of unsupported action indices, and explicit treatment of uncertainty are notable strengths.

Cite this project

@misc{coskun2026containment,
  title = {{The Containment Burden Sits on the Wrong Side of the Boundary \& AI Escape Detection Harness}},
  author = {Barış Ceyhun Coşkun and Emir Raşit Gökçe and Hamza Efe Şahinbaş and Efe Kırbaş and Ayşe Eda Kaya},
  year = {2026},
  month = sep,
  note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/the-containment-burden-sits-on-the-wrong-side-of-the-boundary-ai-escape-detection-harness-7luf}},
  url = {https://apartresearch.com/sprints/projects/the-containment-burden-sits-on-the-wrong-side-of-the-boundary-ai-escape-detection-harness-7luf}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026